This page is an educational summary for professionals working with AI. It is not the law and not legal advice. Always work from the current authoritative text linked below.
What does CPS 220 do?
Prudential Standard CPS 220 Risk Management requires each APRA-regulated institution, and the Head of a group, to maintain a risk management framework appropriate to its size, business mix and complexity. The Board is ultimately responsible for that framework and must approve the risk appetite statement, risk management strategy and business plan. The standard was made by determination No.1 of 2019 on the Federal Register of Legislation and commenced on 1 July 2019, unamended since.
Who does it bind?
Authorised deposit-taking institutions, general insurers, life companies and friendly societies, private health insurers, and their non-operating holding companies. Registrable superannuation entity licensees are expressly excluded: SPS 220 Risk Management covers them instead.
What do practitioners get wrong?
First, treating CPS 230 as having replaced CPS 220. It did not: the current CPS 230 determination places operational risk management inside the risk management framework required under CPS 220 and SPS 220. Second, applying CPS 220 to superannuation trustees, which footnote 1 of the standard expressly routes to SPS 220.
Where does AI use touch it?
CPS 220 requires the framework to control or mitigate "all internal and external sources of material risk", which is where AI model, vendor and data risks land, and Boards relying on AI-assisted reporting still own the framework. See board risk declarations, GenAI approval expiry triggers and CPS 230.
Bottom line
CPS 220 is the enterprise risk backbone for APRA-regulated institutions: Board-owned framework, risk appetite and strategy. CPS 230 slots into it rather than replacing it, and AI risk belongs inside that framework.
TheAICommand. Intelligence, At Your Command.
